What is CVE-2026-15334?
CVE-2026-15334 is a stored XSS vulnerability in the Cozy Blocks plugin for WordPress, affecting versions up to 2.2.11. It occurs via the 'icon.view' Block Attribute due to insufficient input sanitization and output escaping. Immediate update is required.
Azərbaycanca: CVE-2026-15334, WordPress üçün Cozy Blocks plaginində saxlanılan XSS zəifliyidir. Bu, 'icon.view' blok atributunda yetərsiz input sanitization və output escaping səbəbindən baş verir. 2.2.11-ə qədər bütün versiyalar təsirlənir — plagini dərhal yeniləmək lazımdır.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
What versions of the Cozy Blocks plugin are vulnerable to CVE-2026-15334?
All versions up to 2.2.11 are affected.
Which Cozy Blocks attribute triggers the CVE-2026-15334 vulnerability?
This stored XSS vulnerability occurs via the 'icon.view' Block Attribute.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.